Re: Cryptsetup and hardware accelerated AES-XTS

Eric Biggers <[email protected]> Sat, 20 Jul 2024 10:36:11 -0700
Newsgroups dev.linux.lists.cryptsetup
Message-ID <[email protected]>
On Sat, Jul 20, 2024 at 12:15:23PM +0000, Maxim Fomin wrote:
> Hi!
> 
> Recently linux kernel got[1] faster AES-XTS on modern x86_64 CPUs thanks to VAES and AVX-10/512. I decided to dig deeper into this issue and found the article[2] from 2020 stating that dm-crypt can be configured to use faster (synchronous and hardware accelerated) algorithms with 'capi:' prefix. Can cryptsetup be configured to ask dm-crypt to use hardware accelerated algorithms?
> 
> [1] https://lore.kernel.org/lkml/[email protected]/T/#m83293b2699f9a5da04fc5780ee402191dace3926
> 
> [2] https://blog.cloudflare.com/speeding-up-linux-disk-encryption/
> 
> Best regards,
> Maxim
> 

You don't need to use "capi:".  Just make sure CONFIG_CRYPTO_AES_NI_INTEL=y is
enabled in your kernel (which it already should have been since it was needed
for AES-NI acceleration before), and the new code will be used automatically if
your CPU supports it.

- Eric